Our Commitment to GDPR

ion-point is committed to complying with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Economic Area (EEA) and the United Kingdom.

This page explains how we meet our obligations under GDPR and what rights you have regarding your personal data.

Lawful Basis for Processing

We process personal data under the following lawful bases:

Consent

When you provide explicit consent for us to process your data for specific purposes, such as marketing communications.

Contract Performance

When processing is necessary to fulfill our contractual obligations to you, such as delivering training programs you've enrolled in.

Legitimate Interests

When we have a legitimate interest in processing your data, such as improving our services or preventing fraud, provided this does not override your fundamental rights and freedoms.

Legal Obligation

When processing is necessary to comply with legal obligations, such as tax and accounting requirements.

Your Rights Under GDPR

Right to Access

You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of your request.

Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data.

Right to Erasure (Right to be Forgotten)

You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

Right to Restriction of Processing

You have the right to request that we limit how we use your personal data in certain situations.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you. We do not engage in automated decision-making of this nature.

How to Exercise Your Rights

To exercise any of your rights under GDPR, please contact us at:

Email: [email protected]

We will respond to your request within one month. In complex cases, we may extend this period by an additional two months, and we will inform you of any such extension.

Data Protection Officer

For any questions or concerns about how we handle your personal data, you can contact our Data Protection Officer at:

Email: [email protected]

Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and audits
  • Access controls and authentication mechanisms
  • Staff training on data protection and security
  • Incident response procedures

Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.

International Data Transfers

When we transfer personal data outside the EEA or UK, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions recognizing equivalent data protection standards
  • Binding Corporate Rules where applicable

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations. Our standard retention periods are:

  • Program participant data: 7 years after program completion
  • Marketing communications data: Until consent is withdrawn
  • Website analytics data: 26 months
  • Financial records: As required by UK tax law (currently 6 years)

Third-Party Processors

We work with carefully selected third-party processors who handle personal data on our behalf. All processors are contractually required to:

  • Process data only according to our instructions
  • Implement appropriate security measures
  • Assist us in meeting our GDPR obligations
  • Delete or return data when the processing is complete

Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority.

In the UK, the relevant authority is:

Information Commissioner's Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113

Updates to This Page

We may update this GDPR compliance page periodically to reflect changes in our practices or legal requirements. Please check this page regularly for updates.

Last updated: June 2, 2026